Back to skill

Security audit

Schema Manager

Security checks for vulnerabilities and agentic risk

Overview

This skill is a database migration helper, but it can run destructive database changes automatically without sufficient review controls.

Review this carefully before installing. Use it only on disposable or backed-up databases unless it is changed to validate in an isolated database, quote SQL identifiers safely, generate reports by default, and require explicit approval before writing migration files or dropping indexes.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/manage.py:49
Finding

SQL Injection Through Unquoted Database Index Identifiers

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/manage.py:26
Finding

Pending Migration Validation Executes Untrusted SQL Against the Target Database

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/manage.py:63
Finding

Generated Cleanup Migration Can Overwrite Existing Files or Follow Symbolic Links

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/manage.py:7
Finding

Legitimate Indexes Are Automatically Dropped Based Only on Name Fragments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This is a true security and safety issue because the declared behavior understates materially destructive actions: generating new migration files, dropping indexes, and not actually applying pending migrations as advertised. In a database administration context, behavior-description mismatch is especially dangerous because operators may authorize execution expecting validation or routine migration application, while the skill can silently perform schema-altering actions that affect integrity, availability, and recovery procedures.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The validation phase reads each pending migration and runs it with executescript() on the live target database connection, which means untrusted migration SQL is actually executed rather than parsed or sandbox-checked. Although the code rolls back afterward, migration scripts can still trigger dangerous side effects such as PRAGMAs, DDL behavior, resource exhaustion, or partial/non-transactional effects depending on SQLite semantics, making 'validation' effectively code execution against production state.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script goes beyond analysis and automatically generates DROP INDEX statements, writes them as a migration file, and immediately executes them. This creates an unsafe path where heuristically identified index names are treated as redundant and deleted without review, enabling accidental performance degradation or disruption if naming patterns match legitimate indexes.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill appears capable of reading and writing files but does not declare any tool scope or permission boundaries. For a schema-management skill that can generate migration files, missing explicit scoping increases the risk of unintended filesystem access, privilege creep, and misuse by downstream agents or operators who cannot accurately assess what the skill is allowed to do.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description does not clearly warn that it can modify the target database and create cleanup migrations, despite operating in a high-impact schema-management context. Without an explicit warning, users may invoke it in production or against sensitive databases without understanding that it can perform destructive or hard-to-reverse changes such as dropping indexes, which can impair performance or break application assumptions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code is presented as index analysis, but the subsequent logic performs destructive cleanup by dropping indexes. This mismatch is dangerous because operators or upstream automation may invoke the tool expecting read-only diagnostics, while it actually mutates schema state and can remove important indexes unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script writes a migration file and applies destructive schema changes with no user-facing warning, dry run, or confirmation step. In the context of a schema-management skill, this is especially risky because users may reasonably expect controlled migration workflows, and silent index deletion can cause operational outages or hard-to-diagnose performance regressions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.